Patent · US Active

System and method of anomaly detection with categorical attributes

US9449483B2 · kind B2 · utility

0Cited by
15References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 9, 2015
Grant dateSep 20, 2016
Priority date
Expiry dateApr 9, 2035

Classification

  • Technology area (CPC Y)Emerging Cross-Sectional Technologies
  • CPC primaryY10S707/952
  • WIPO fieldControl
  • WIPO sectorInstruments

Abstract

A method and apparatus are provided where the method includes detecting a plurality of events related to the activities of users within a security system, wherein the events are defined by a plurality of attributes, wherein at least one attribute is categorical, and wherein a data distance between events is a function of event attributes, evaluating the detected events using a density based anomaly detection method f(r), where r is a size of a neighborhood around a data point, comparing a value of the evaluated expression with a margin threshold value (msg(r)), and setting an alarm upon detecting that the value exceeds the threshold value.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.